Stego in TCP retransmissions

I just started reading an interesting new paper out of the Warsaw University of Technology entitled Hiding Information in Retransmission.  This got me to thinking, even those of us who have extensive monitoring of our network rarely will have the capability to compare retransmitted packets to the original to detect this.  A really interesting idea.  The abstract can be found here and the paper itself here.

I will be teaching next: Reverse-Engineering Malware: Malware Analysis Tools and Techniques - SANS Tokyo Autumn 2022

Jim

423 Posts
ISC Handler
May 28th 2009

Sign Up for Free or Log In to start participating in the conversation!